feat(auth): coordinate canonical projection publication
This commit is contained in:
@@ -1,16 +1,44 @@
|
||||
package authconfig
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"errors"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/authprojection"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/safeio"
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/testsupport"
|
||||
)
|
||||
|
||||
func TestLoadSnapshotBytesReturnsValidatedCopiedCanonicalBytes(t *testing.T) {
|
||||
for _, fixture := range []struct{ name, auth, users string }{
|
||||
{"local", defaultAuthYAML, registryYAML(adminUserYAML("admin", "Admin", true, "admin"))},
|
||||
{"oidc", "version: 1\nmode: oidc\npublicUrl: https://example.invalid\n", ""},
|
||||
} {
|
||||
t.Run(fixture.name, func(t *testing.T) {
|
||||
directory := writeAuthFiles(t, fixture.auth, fixture.users)
|
||||
snapshot, err := loadSnapshotBytes(directory)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if snapshot.Mode != fixture.name || !bytes.Equal(snapshot.Auth, []byte(fixture.auth)) || !bytes.Equal(snapshot.Users, []byte(fixture.users)) {
|
||||
t.Fatal("loadSnapshotBytes() did not preserve the validated canonical bytes")
|
||||
}
|
||||
if _, err := authprojection.NewSnapshot(snapshot.Mode, snapshot.Auth, snapshot.Users); err != nil {
|
||||
t.Fatalf("loadSnapshotBytes() returned invalid projection data: %v", err)
|
||||
}
|
||||
snapshot.Auth[0] ^= 1
|
||||
onDisk, err := os.ReadFile(filepath.Join(directory, authFileName))
|
||||
if err != nil || !bytes.Equal(onDisk, []byte(fixture.auth)) {
|
||||
t.Fatal("loadSnapshotBytes() returned aliasing canonical storage")
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
const publicFixedHash = "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4"
|
||||
|
||||
func TestLoadReadsTheStrictLocalConfigurationAndRegistry(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user